Contract Data Requirements List
A Contract Data Requirements List (CDRL) is a Department of Defense document that lists all the data items a contractor must deliver to the government during the performance of a contract. These deliverables can include items such as technical reports and other data products. The CDRL becomes part of the contract and tells the contractor what data must be provided and in what form.
The CDRL is the authorized, standardized list identifying the data deliverables a contractor is required to provide to the government under a DoD contract. It generally serves as the standard format for identifying potential data requirements in a solicitation and deliverable data requirements in the resulting contract, forming part of the contract in conjunction with applicable Data Item Descriptions (DIDs), which specify the content and format of each listed data item. Note that this entry describes the CDRL concept as reflected in the cited evidence; it does not cover the specific form number, preparation procedures, or agency-specific tailoring, which the reader should verify against current authoritative DoD acquisition guidance.
Why it matters
The CDRL is the mechanism that transforms a government data need into an enforceable contractual obligation. Because it becomes part of the contract, the CDRL is what makes a contractor legally accountable for delivering specified data items in a defined form. For compliance officers and contracting personnel, this matters because data deliverables often carry security and handling implications: a technical report or other data product delivered under a CDRL may contain or constitute Controlled Unclassified Information (CUI), which can trigger safeguarding and marking obligations separate from the CDRL itself. The CDRL identifies what must be delivered; it does not by itself establish the full scope of how that data must be protected, so readers should not treat a CDRL as a substitute for reviewing applicable security clauses and CUI requirements.
Misunderstanding the relationship between the CDRL and the Data Item Descriptions (DIDs) is a common and consequential error. The CDRL lists the required data items, while the applicable DIDs specify the content and format of each item; the two work together, and neither alone fully defines a deliverable. Treating the CDRL as if it stood in for the detailed content requirements of a DID, or vice versa, can lead to non-conforming deliverables and contractual disputes. Because the evidence digest does not establish specific form numbers, preparation procedures, or tailoring rules, practitioners should confirm those details against current authoritative DoD acquisition guidance rather than relying on general summaries.
Properly constructed CDRLs also support downstream compliance and oversight activities. Clear identification of data deliverables gives authorizing officials, auditors, and program personnel a defined basis for verifying that required information has been provided in the correct form. Ambiguity or omission at the CDRL stage tends to propagate into contract performance problems, which is why accuracy in identifying data requirements at solicitation and contract award is generally emphasized in DoD acquisition practice.
Who it's relevant to
Inside CDRL
Common questions
Answers to the questions practitioners most commonly ask about CDRL.